top of page
Search

Rethinking Security Awareness

Each October, organizations globally participate in Cybersecurity Awareness Month. Employees are required to complete training, view phishing-related videos, and undertake quizzes aimed at reinforcing security best practices. Organizations often report training completion rates of 95% or higher; however, the headlines suggest a different reality.

Significant breaches frequently originate from phishing emails. Employees continue to approve fraudulent MFA requests, and sensitive data is mistakenly shared with incorrect recipients. Attackers persist in exploiting human behavior as one of the simplest entry points into an organization.

This raises a challenging question: If we have invested so heavily in security awareness, why do these attacks continue to succeed?

Perhaps the problem is not a lack of employee awareness. Instead, we may have misconceived the true objective of security awareness.


Awareness Isn't the Same as Action

Most security awareness programs are built on a simple assumption:


If people know what the right thing to do is, they'll do it.


It's an appealing idea, but human behavior is rarely that straightforward.

Consider everyday life. Most people know they should exercise regularly, avoid distracted driving, and eat healthier meals. Yet knowledge alone doesn't always translate into action. Behavior is shaped by context, habits, stress, incentives, and environment.

Cybersecurity is no different.

Employees don't make security decisions while sitting in a classroom. They make them while responding to dozens of emails, juggling meetings, managing deadlines, and trying to get through an already busy day.

The challenge isn't a lack of information; it's the reality in which decisions are made.


The Problem with Compliance-Based Awareness

Many organizations continue to treat awareness as a compliance obligation rather than addressing it as a behavioral challenge.

Success is frequently evaluated using metrics such as:

The percentage of employees who have completed training

Quiz scores

The number of phishing simulations completed

Annual policy acknowledgements

While these metrics are straightforward to gather, they provide limited insight into actual behavior under pressure.

Successfully passing a quiz does not necessarily indicate that an individual will identify a sophisticated phishing attempt during a busy workday.

Completion does not equate to preparedness.


Attackers Understand Human Behavior Better Than We Do

One reason phishing remains so effective is that attackers rarely rely on technical sophistication alone. Instead, they exploit predictable patterns in human decision-making.

They create urgency.

They imitate authority.

They leverage familiarity.

They exploit trust.

A phishing email isn't successful because it's technically impressive. It's successful because it feels believable enough to trigger an automatic response before careful analysis takes place.

In many ways, attackers study human behavior as carefully as defenders study malware.

Perhaps it's time defenders did the same.


Security Should Fit Human Behavior

When a security incident occurs, the first response is often to retrain employees.

But what if we asked a different question?

Instead of asking: Why did the employee make a mistake?

What if we asked:

Why did our systems make that mistake so easy to make?

Good security isn't about expecting perfect people.

It's about designing systems that support imperfect people.

This might mean:

Reducing unnecessary MFA prompts to prevent fatigue.

Making suspicious emails easier to report.

Simplifying security policies so they're practical, not theoretical.

Providing just-in-time guidance when risky actions occur.

Designing workflows where the secure choice is also the easiest choice.

Security should work with human behavior not against it.


The AI Era Changes Everything

Artificial intelligence is transforming the realm of cyber threats.

Attackers are now able to produce convincing phishing emails in seconds, imitate writing styles, replicate voices, and fabricate realistic fake identities with little effort.

As deception becomes more advanced, depending solely on awareness training is becoming increasingly inadequate.

The future of security awareness will demand more than just teaching employees to "identify the phishing email."

It will involve assisting people in thinking critically, verifying information, and detecting manipulation even when it appears genuine.

Awareness must shift from memorizing rules to cultivating judgment.

Rethinking Success

Perhaps we've been measuring the wrong outcomes.

Instead of asking:

Did employees complete the training?

Did they pass the quiz?

Did phishing click rates decrease?

We should also ask:

Do employees feel comfortable reporting suspicious activity?

Can they pause and question unusual requests without fear of criticism?

Have we designed processes that reduce unnecessary cognitive burden?

Are we building a culture where security is everyone's responsibility, not just the security team's?

These questions are harder to answer but they're far more meaningful.


Security awareness has never been simply about teaching people to recognize threats. At its best, it is about helping people make better decisions in moments of uncertainty.

Organizations that continue to treat awareness as an annual compliance exercise may satisfy auditors, but they risk missing the deeper objective: creating an environment where secure behavior becomes the natural choice.

As cyber threats continue to evolve, perhaps it's time we stopped asking how much our employees know and started asking a different question:

Are we building systems, cultures, and processes that make secure decisions easier to make?

Because in the end, security awareness isn't measured by what people remember after training.

It's measured by what they do when it matters most.


 
 
 

Comments


Explore More Insights
bottom of page